2

Remote Exploit Development Jobs in New York (NOW HIRING)

Contract Compensation: $17-$25/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

Contract Compensation: $17-$25/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

Remote Role Responsibilities * Red team conversational AI models and agents by performing ... Cybersecurity skills: penetration testing, exploit development, reverse engineering. * Socio ...

Contract Compensation: $17-$25/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

This is a remote position based in the United States, with occasional travel for conferences, team ... Track how threat actors exploit current events, emerging technologies, and changes in the threat ...

... exploit and what your defenses stop, then closes real gaps with ready-to-deploy fixes and ... Be part of a global remote team who is taking on Exposure Validation and a growing market segment.

The Bigger Picture Join a 100% remote, highly specialized offensive security team where you will ... Offensive Security identifies weaknesses so the business can fix them before adversaries exploit ...

... exploit and what your defenses stop, then closes real gaps with ready-to-deploy fixes and ... Be part of a global remote team who is taking on Exposure Validation and a growing market segment.

The Bigger Picture Join a 100% remote, highly specialized offensive security team where you will ... Offensive Security identifies weaknesses so the business can fix them before adversaries exploit ...

The Bigger Picture Join a 100% remote, highly specialized offensive security team where you will ... Offensive Security identifies weaknesses so the business can fix them before adversaries exploit ...

Remote Exploit Development information

What is the difference between Remote Exploit Development vs Penetration Tester?

AspectRemote Exploit DevelopmentPenetration Tester
CredentialsKnowledge of security vulnerabilities, programming, and sometimes certifications like OSCPCertifications like OSCP, CEH, and strong technical skills
Work EnvironmentTypically focused on developing exploits in controlled environments or labsConducts security assessments in client or corporate networks
Industry UsageUsed mainly in security research, offensive security, and exploit developmentUsed in cybersecurity, risk assessment, and compliance

Remote Exploit Development involves creating and testing exploits for vulnerabilities, often in a research or offensive security context. Penetration Testers simulate attacks to identify security weaknesses. While both roles require strong technical skills and security knowledge, exploit developers focus on developing exploits, whereas penetration testers perform broader security assessments.

What are the most commonly searched types of Exploit Development jobs in New York?

The most popular types of Exploit Development jobs in New York are:

What are popular job titles related to Remote Exploit Development jobs in New York?

For Remote Exploit Development jobs in New York, the most frequently searched job titles are:

What cities in New York are hiring for Remote Exploit Development jobs?

Cities in New York with the most Remote Exploit Development job openings:

Cybersecurity Researcher - Fully Remote | Upto $250/hr

Mercor

New York, NY • Remote

$250/hr

Full-time

Posted 12 days ago


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Cybersecurity Research Expert – Offensive Security & Vulnerability Research
Type: Contract
Compensation: $200–$250/hour
Location: Remote

Role Responsibilities

  • Evaluate AI-generated analyses of complex cybersecurity scenarios, exploits, and vulnerability reports.
  • Review technical writeups for correctness, exploitability, and mitigation quality.
  • Validate vulnerability root-cause analysis across software, operating systems, networking, cloud, and web applications.
  • Provide structured feedback on security reasoning, exploit chains, and defensive recommendations.
  • Contribute to benchmark development for advanced AI security capabilities.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • Member of a top-ranked Capture The Flag (CTF) team with demonstrated competitive achievements.
  • Discoverer or co-author of CVEs affecting widely used open-source or commercial software.
  • Publicly recognised bug bounty researcher with findings accepted by major programs (e.g., Google, Microsoft, Apple, Meta, GitHub, Mozilla, Chromium, Kubernetes, Linux Foundation, etc.).
  • Research experience at a well-respected security laboratory or academic research group.
  • Author of high-quality security research publications, conference papers, or widely cited technical writeups.
  • Strong understanding of exploit development, reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.

Preferred

  • Professional experience in offensive security, application security, vulnerability research, product security, or security engineering.
  • Experience with reverse engineering tools such as IDA Pro, Ghidra, Binary Ninja, or Radare2.
  • Familiarity with fuzzing, symbolic execution, static analysis, or dynamic analysis frameworks.
  • Experience with Linux internals, Windows internals, browser security, cloud security, embedded security, or mobile security.
  • Strong programming skills in C/C++, Rust, Python, Go, or Java.
  • Excellent written communication and ability to explain complex security concepts clearly.

Nice to Have

  • Hall of Fame recognition from major bug bounty programs.
  • Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar conference presentations/publications.
  • Maintainer or significant contributor to well-known open-source security tools.
  • Offensive Security certifications (OSCP, OSEP, OSCE3), GIAC certifications, or equivalent credentials.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.